Being audit-ready means every material figure on your financial statements ties back to a signed reconciliation, that reconciliation sits in a centralised repository, and everything is mapped against a Prepared-by-Client (PBC) list before the auditor asks for it. The single first move is to build that PBC list and folder structure now, ideally 90 days before fieldwork starts, not the week the engagement letter arrives.
TL;DR:
- Building a comprehensive PBC list 90 days before fieldwork starts is crucial to ensure all material figures are linked to signed reconciliations and properly organized.
- Reconciliations for bank accounts, receivables, payables, payroll, and fixed assets are the most common bottlenecks, so thorough sign-offs and explanations are essential.
- Prior-year unresolved issues should be addressed proactively with documented root causes, remedial actions, and ongoing evidence to prevent delays during audit fieldwork.
- Clear communication, designated coordinators, early setup of portal access, and daily open-item tracking significantly reduce request delays and improve collaboration.
- Companies with scattered evidence and unclear ownership often fail to meet PCAOB documentation standards; systematic workflows and staff training are key to compliance.
Table of Contents
- What should be on your master audit readiness checklist?
- How long does audit preparation actually take?
- How do you structure PBC schedules and the document repository?
- What internal controls evidence do auditors actually expect?
- How do you handle auditor communication and fieldwork logistics?
- What does PCAOB AS 1215 actually require?
- How Keystoneconsulting speeds evidence assembly
- What does a pre-audit self-assessment involve?
- Why staff training matters for audit readiness
- How do you handle confidential information during an audit?
- What are the most common pitfalls in audit preparation?
- How should you address prior-year findings and remediation?
- Pragmatic lessons from two decades in governance
- A practical way to run this checklist at scale
- Authoritative standards and downloadable checklists
- Sources
What should be on your master audit readiness checklist?
A proper PBC master list is organised by category, not by whoever happens to email you first. Auditors work through requests in batches, and a well-structured PBC checklist reduces the follow-up questions that eat into fieldwork days. Below is the categorised version most controllers end up building by trial and error. Build it deliberately instead.
Financial statements and trial balance items
Your auditor needs a clean starting point before anything else makes sense.
- Final trial balance tied to the general ledger, with any post-closing adjustments flagged
- Draft financial statements, including comparative prior-year figures
- General ledger detail for the full period under audit, exportable by account
- A lead schedule mapping each financial statement line to its supporting reconciliation
Reconciliations and supporting schedules
This is where most audits either speed up or grind to a halt. Every material balance needs a reconciliation with reviewer sign-off, not just a spreadsheet someone filled in once and forgot about.
- Bank reconciliations for every account, with outstanding items explained
- Accounts receivable ageing with a reconciliation to the GL control account
- Accounts payable ageing and a subledger-to-GL tie-out
- Payroll reconciliation covering gross wages, withholdings, and employer contributions
- Fixed asset roll-forward showing additions, disposals, and depreciation
Skipping any one of these is the single most common reason financial audit preparation runs over schedule. Auditors treat an unreconciled balance as an open risk, and open risks generate extra testing.
Payroll, tax and benefits documentation
- Payroll tax returns filed during the period, with proof of payment
- Benefits enrolment records and any related accrual calculations
- Employment tax reconciliations, including unemployment insurance filings
- Independent contractor payments and corresponding 1099 filings where applicable
Fixed assets, leases, loans and contract schedules
- Lease schedules showing right-of-use asset and liability calculations
- Loan agreements with amortisation schedules and covenant compliance calculations
- Material contracts signed or renewed during the period, especially anything with revenue recognition implications
- Capital expenditure approvals matched against the fixed asset roll-forward
Disclosure and footnote drafts
Auditors expect draft footnotes, not blank templates waiting for their input. Draft early on:
- Significant accounting policies, especially anything that changed during the period
- Related-party transactions and the approval trail behind them
- Contingencies, commitments, and subsequent events
- Segment reporting where it applies
Controls evidence and file naming
Every schedule above needs a visible reviewer trail. Name files consistently: something like BankRecon_OperatingAcct_Dec2026_Reviewed.xlsx tells an auditor everything they need before opening it. A file named Copy of Copy of recon (2).xlsx tells them the opposite, and invites more scrutiny, not less.
Pro Tip: Build one master index spreadsheet that lists every PBC item, its owner, its due date, and a direct link to the file. Auditors will ask for a PBC tracker anyway. Building it first means you control the format instead of reworking theirs.
How long does audit preparation actually take?
Ninety days is the commonly recommended window for a financial statement audit, and it holds up whether you're a mid-sized construction firm or a healthcare provider under HIPAA oversight. The phases below assume that runway. If you've got less, the triage note at the end tells you what to cut first.
-
Phase 1, days 90 to 61: foundation. Stand up the centralised repository and folder structure. Assign an owner to every PBC line item by name, not by department. Flag high-risk areas early, such as any account with a prior-year adjustment or a new revenue stream that hasn't been through an audit cycle yet. This is also when you confirm the audit coordinator role, the single person who owns communication with the audit team from here through sign-off.
-
Phase 2, days 60 to 31: reconciliation and evidence. Complete reconciliations for every material balance and get reviewer sign-offs on each one. Pull together internal controls evidence: approval emails, access logs, change history reports. Draft the disclosure footnotes. This phase is where most of the actual work happens, and it's also where organisations most often run out of time because they treated Phase 1 as optional.
-
Phase 3, days 30 to 0: packaging and rehearsal. Finalise every schedule, confirm every sign-off is dated and legible, and run an internal walkthrough as if you were the auditor opening the file cold. Address anything that doesn't explain itself without a phone call. Confirm portal access, bank confirmation requests, and the fieldwork schedule with the audit team.
Once fieldwork starts, set prompt response expectations to auditor requests: immediate or next-business-day for simple requests and a quick turnaround for more detailed analyses. Log every open item in one shared list, visible to both sides, so nothing gets asked twice and nothing gets forgotten.
If you've got less than 60 days: triage ruthlessly. Reconciliations for material balances come first, full stop. Controls evidence and footnote drafts come second. Anything cosmetic, like refining file naming conventions, comes last or gets skipped entirely this cycle. An organisation that treats readiness as a continuous, monthly habit rather than an annual scramble rarely finds itself in this position twice.
How do you structure PBC schedules and the document repository?
Every PBC schedule should answer three questions on sight: does this tie to the general ledger, what are the reconciling items, and who reviewed it. If a schedule can't answer those without a follow-up call, it isn't finished.
- GL tie-out: the schedule's ending balance should match the trial balance line it supports, with the account number visible
- Reconciling items: anything that doesn't tie should be listed with an explanation and, where relevant, supporting evidence of its own
- Reviewer sign-off: a name, a date, and ideally an initial or digital signature on the file itself, not buried in an email thread
Folder structure matters more than most finance teams assume. A flat folder with 40 files dumped in named after whoever last touched them is functionally the same as no folder at all. Structure it by category (Financials, Reconciliations, Payroll, Fixed Assets, Contracts, Disclosures, Controls Evidence) with subfolders by month or account where volume justifies it. If you're using a secure portal for exchange, mirror that same category structure inside it so the auditor's view matches yours exactly.
For common schedules, the pattern repeats: a bank reconciliation folder holds the bank statement, the reconciliation itself, and evidence of any outstanding cheques or deposits in transit. An accounts receivable folder holds the ageing report, the GL tie, and any collection notes on items over 90 days. A fixed asset folder holds the roll-forward, the depreciation schedule, and purchase invoices for anything added during the period.
Cross-referencing ties it together. Every reconciliation should reference the source document it draws from, by file name, so a reviewer, internal or external, can trace a number back to its origin in under a minute. Auditors value evidence that explains itself without a walkthrough call, and that's exactly what a well-cross-referenced schedule delivers.
What internal controls evidence do auditors actually expect?
Auditors don't just want to know your controls exist on paper. They want proof those controls operated consistently throughout the period, because that proof is what lets them reduce substantive testing and, in turn, shrink the time and cost of the engagement.
Segregation of duties is the starting point: no single person should be able to initiate, approve, and record the same transaction. Where a smaller organisation genuinely can't split those duties across enough people, documented compensating controls are acceptable, provided they're applied consistently and evidenced every single time, not just when someone remembers.
The evidence auditors actually want to see includes:
- Approval emails or system logs showing who signed off on payments above a threshold, and when
- Access logs showing who could edit the general ledger, and confirmation that list was reviewed periodically
- Change history reports for accounting system configurations, particularly anything affecting revenue recognition
- Records of periodic account reviews, such as a monthly reconciliation review meeting with minutes or sign-offs
- Evidence that any control failure identified mid-year was remediated, with a date and a description of the fix
Document remediation properly. If a control failed in March and you fixed it in April, keep the email trail, the updated procedure, and evidence the new procedure actually ran in May and June. An auditor who sees remediation evidence closes that line of enquiry. One who sees a gap with no explanation opens a much longer one, internal control documentation being one of the clearest signals of overall audit maturity an external reviewer can assess quickly.
Good controls evidence genuinely shrinks scope. An auditor who can rely on your controls tests fewer transactions in detail. One who can't relies entirely on substantive testing, which means more sampling, more questions, and a longer, more expensive fieldwork period.
How do you handle auditor communication and fieldwork logistics?
Most delays during fieldwork have nothing to do with the numbers. They come from unclear ownership of requests and slow turnaround on simple questions.
-
Confirm scope and format before fieldwork starts. Agree the reporting framework, the materiality threshold, and whether fieldwork happens on-site, remotely, or in a hybrid arrangement. Get this in writing from the engagement letter, not a verbal understanding from a kickoff call.
-
Appoint one audit coordinator. This person owns the PBC tracker, routes requests to the right internal owner, and enforces response SLAs. A designated coordinator with a defined folder structure consistently shortens fieldwork duration compared with ad hoc request handling.
-
Set up portal access and confirmations early. Bank confirmation requests often take longer than expected because banks have their own processing queues. Send them the moment the audit is scheduled, not the week fieldwork begins. Confirm the secure file exchange method, whether that's a dedicated portal or an encrypted transfer protocol, before the first request lands.
-
Run a daily open-items list. Every outstanding request, its owner, and its status should live in one shared document both sides can see. Escalate anything stalled more than 48 hours to a manager, and if a request seems out of scope, raise it with the engagement partner directly rather than letting it sit unanswered.
What does PCAOB AS 1215 actually require?
AS 1215 sets the documentation bar auditors work to, and understanding it helps you anticipate what "sufficient" evidence looks like from their side of the table.
PCAOB Standard AS 1215 requires auditors to document the procedures performed, the evidence obtained, the conclusions reached, and the identity and date of the person who reviewed the work. Documentation must be assembled by a defined completion date, and retained for seven years afterwards.
That seven-year retention rule matters for you too, not just the auditor. If a gap surfaces after the report date, whether through a regulator enquiry or an internal review, you need the same underlying schedules the auditor relied on, retrievable in the same structure. Build your own retention policy to match that seven-year standard rather than defaulting to whatever your document management system happens to keep by default.
How Keystoneconsulting speeds evidence assembly
Twenty years of governance work across healthcare, construction, and facilities management surfaces the same bottleneck repeatedly: teams have the evidence, but it's scattered across inboxes, shared drives, and someone's personal spreadsheet. Keystoneconsulting's Operational Readiness Review evidence checklist and maturity scoring gives teams a repeatable rubric for triaging exactly which gaps matter most, ranked by risk rather than by whoever complains loudest.
The Videra platform maps operational workflows directly to the evidence artefacts an auditor will ask for, which cuts the time regulated teams spend hunting for approval trails and access logs during the exact weeks they can least afford it.
What does a pre-audit self-assessment involve?
Running your own mock audit before the real one starts is the cheapest insurance available. Pick a handful of material accounts, ideally the ones with the most complexity or the most prior-year adjustments, and pull the full PBC package for each as if you were the external reviewer opening it cold.

Ask the same questions an auditor would ask: does this reconciliation tie to the GL, is there a reviewer signature, does the supporting schedule explain every reconciling item without a phone call? If the answer is no anywhere, you've just found a gap with weeks to fix it instead of hours.
A useful technique borrowed from information security audits is the structured pre-audit walkthrough, where a pre-audit assessment framework forces reviewers to score readiness against defined criteria rather than a gut feeling. Applying that same discipline to a financial or compliance audit, scoring each PBC category on a simple scale rather than a vague "mostly ready", surfaces blind spots a casual review misses.
Rotate who runs the self-assessment each cycle if you can. The person who prepared a schedule is the worst-placed person to spot what's missing from it, because they already know the story behind every number. A fresh reviewer asks the questions an external auditor actually will.
Why staff training matters for audit readiness
A brilliant checklist is worthless if the people executing it don't understand why each step exists. Staff who see reconciliation and sign-off as bureaucratic box-ticking will do it late, inconsistently, or not at all once deadline pressure builds elsewhere.
Training needs to cover two things: the mechanics of what's expected (how to build a reconciliation an auditor can follow without a call) and the reasoning behind it (why a missing reviewer signature turns a five-minute review into a two-day escalation). Staff who understand the second part tend to get the first part right without being told twice.
New hires joining finance, operations, or compliance roles mid-cycle need a specific onboarding step covering PBC expectations, not a general induction that mentions audits in passing. And refresh training annually even for experienced staff, because audit standards and internal processes both shift, and what counted as sufficient evidence two cycles ago doesn't always hold today.
The organisations that consistently sail through audits aren't the ones with the most sophisticated systems. They're the ones where every person touching a reconciliation already knows what "done" looks like before anyone asks.
How do you handle confidential information during an audit?
Audit fieldwork puts sensitive material in front of external parties by design, payroll detail, contract terms, patient records in healthcare settings, and personally identifiable information across HR files. Handling that correctly is as much a part of audit readiness as any reconciliation.
Start with access control on the repository itself. Not every auditor on the engagement team needs access to every folder, and not every internal reviewer needs access to payroll or personnel files. Set permissions by folder category and review them before fieldwork starts, not after someone notices an oversight.

Redact what genuinely doesn't need to be visible. Social security numbers on payroll schedules, for instance, can often be masked without weakening the evidence an auditor needs to test the control. Where full detail is unavoidable, such as HIPAA-covered patient records in a healthcare audit, confirm the auditor's own data handling and confidentiality obligations are documented in the engagement letter before any file changes hands.
Secure transfer matters as much as access control. Email attachments are the weakest link in most exchange processes. A dedicated portal with logged access, the same one your PBC tracker should already be routing through, keeps a record of exactly who viewed what and when, which matters if a confidentiality question arises later.
What are the most common pitfalls in audit preparation?
The same handful of mistakes recur across organisations of every size, and nearly all of them are avoidable with a bit of foresight.
Waiting until the engagement letter arrives to start preparing is the biggest one. By the time fieldwork is scheduled, there usually isn't enough runway left to fix a genuinely messy reconciliation, only to paper over it under time pressure, which auditors notice.
Treating the PBC list as optional guidance rather than a firm deliverable is another. Auditors build their fieldwork schedule around when they expect to receive each item. A late PBC delivery doesn't just delay that one item, it pushes the entire engagement timeline and often triggers additional fees for the extra days on-site.
Inconsistent file naming and folder chaos cost more time than most teams realise. An auditor who has to ask "which version of this reconciliation is current?" three separate times has just added three separate delays to a schedule that was already tight.
Ignoring prior-year findings until someone asks about them again is a particularly avoidable pitfall, covered in more detail below. And underestimating how long bank confirmations take, since they depend on a third party's own processing queue, catches almost every organisation out at least once.
How should you address prior-year findings and remediation?
Auditors return to prior-year findings first, almost without exception, because an unresolved issue from last cycle signals a control environment that hasn't matured. Addressing them proactively is one of the highest-leverage things you can do before fieldwork starts.
For every finding raised last cycle, document three things: the root cause, the specific remediation action taken, and evidence that the remediation has actually operated since it was implemented, not just that a policy document was updated. A remediation trail with ongoing monitoring evidence closes a finding far faster than a verbal assurance that "it's fixed now."
Where a finding genuinely hasn't been resolved yet, say so plainly and explain the plan and timeline rather than letting the auditor discover it unannounced during testing. Auditors respond far better to a transparent, in-progress remediation plan than to a surprise repeat finding they have to raise themselves.
Pragmatic lessons from two decades in governance
The organisations that struggle with audits almost never have a numbers problem. They have an ownership problem: nobody was ever named as directly responsible for a given reconciliation, so it drifted until someone noticed under deadline pressure. Fix that one habit, name an owner against every single PBC line, and most of the chaos disappears on its own.
If you take nothing else from this, run a 30-day sprint before your next audit: build the PBC tracker, assign owners, and reconcile just the three largest balance sheet accounts properly. It rarely fails to expose whatever's actually been going wrong.
— Peter
A practical way to run this checklist at scale
Manually chasing every reconciliation, approval email, and access log through spreadsheets and shared drives is the standard approach, and it's exactly why so many teams rebuild the same PBC tracker from scratch every audit cycle. Rather than a generic consultancy sitting outside your team, some consultancies integrate directly with how your teams already work and map that work to the evidence an auditor will actually ask for.

Videra PM turns your operational workflows into auditable trails automatically, so approval evidence, access logs, and sign-offs are already organised by the time your 90-day countdown starts, rather than assembled in a scramble during Phase 2. For healthcare providers managing HIPAA or Joint Commission obligations alongside financial audits, Videra Healthcare applies the same mapped-workflow approach to clinical and lifecycle documentation. If your reconciliations, controls evidence, and PBC schedules are still living across five different systems, request a capability brief through Keystoneconsulting and see what a mapped, audit-ready workflow actually looks like for your sector.
Authoritative standards and downloadable checklists
For the documentation rules auditors themselves work to, read PCAOB AS 1215 directly rather than a summary of it. For a ready-to-adapt master list, the Qualio audit readiness checklist offers a downloadable starting point, alongside the 90-day preparation guide referenced throughout this article.
Sources
- AS 1215: Audit documentation (PCAOB)
- Audit readiness checklist (HelpfuICFO)
- Audit preparation checklist: the 90‑day guide (TallyScan)
- Financial audit preparation checklist (LedgerOne CFO)
